CVE Vulnerabilities

CVE-2022-48365

Improper Privilege Management

Published: Mar 12, 2023 | Modified: Mar 16, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Digital_experience_platform Ibexa 3.3.0 (including) 3.3.28 (excluding)
Digital_experience_platform Ibexa 4.2.0 (including) 4.2.3 (excluding)
Ez_platform Ibexa 2.5.0 (including) 2.5.31 (excluding)
Ez_platform_kernel Ibexa 1.3.0 (including) 1.3.26 (excluding)
Ez_platform_kernel Ibexa 7.5.0 (including) 7.5.30 (excluding)

Potential Mitigations

References